$npx skillfedfor your agent

pyhanko-certvalidator

Validates X.509 certificates and paths; forked from wbond/certvalidator

Worth itPyPI CryptographyReleased Jul 20266.3M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyhanko_certvalidator-0.31.4-py3-none-any.whl
v0.31.4 · released 2026-07-25 · Python >=3.10 · 5 runtime deps: asn1crypto, oscrypto, cryptography, uritools, requests

Yes. The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides comprehensive X.509 validation with low install friction. Suitable for production use in PKI-aware applications. Note that the synchronous API is deprecated in favor of async equivalents, so new code should plan for async patterns.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or higher.
  • Most high-level APIs are now async-first; synchronous wrappers exist but are deprecated.
  • Low friction install with five stable runtime dependencies.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions; suitable for most projects.

last release 2026-07-25 (20 days) · last repo commit 2026-08-14 · 754 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,294,287 downloads/mo, #1,937 on PyPI

Verify before relying

pip install pyhanko-certvalidator

from pyhanko_certvalidator import CertificateValidator
validator = CertificateValidator()
# Use validator.validate_usage() or async equivalents for certificate validation
  • Whether the synchronous API wrappers are stable enough for production use despite deprecation status
  • Performance comparison between requests-based (default) and aiohttp-based OCSP/CRL clients
  • Completeness of documentation for migration from synchronous to async patterns
Same gist for agents: .md · .json

What it is and what it does

pyhanko-certvalidator is a Python library for validating X.509 certificate chains, originally forked from wbond/certvalidator but significantly evolved for use in pyHanko. It performs comprehensive path validation including signature verification (RSA, DSA, ECDSA, EdDSA), name chaining, validity date checks, and extension processing. The library supports revocation verification through both CRL (including indirect and delta CRLs) and OCSP (including delegated responders), with configurable failure modes and response caching. It can validate certificates at a specific point in time, enforce name constraints, and handle attribute certificates.

The library has been refactored to use asynchronous I/O throughout, though synchronous wrappers remain available for backward compatibility. It depends on asn1crypto, cryptography, oscrypto, uritools, and requests. The default OCSP and CRL clients use requests for HTTP operations, with an optional aiohttp-based implementation available for more efficient async use. Bug reports and questions are routed through the pyHanko project rather than this repository directly.

Use it for

  • Validate certificate chains in PKI-aware applications before trusting certificates for TLS or code signing
  • Perform revocation checks via CRL or OCSP to ensure certificates have not been compromised or revoked
  • Validate certificates as they were at a specific historical date for compliance or forensic purposes
  • Enforce certificate policy constraints and name constraints in security-critical workflows
  • Build certificate path validation into document signing or verification tools (e.g., PDF signing)

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides comprehensive X.509 validation with low install friction. Suitable for production use in PKI-aware applications. Note that the synchronous API is deprecated in favor of async equivalents, so new code should plan for async patterns.

Install

pyhanko-certvalidator on PyPI

Before you install

Low friction install with five stable runtime dependencies. Actively maintained with a release within the past month and recent commits. Supports current Python versions (3.10+).

Requires Python 3.10 or higher. Most high-level APIs are now async-first; synchronous wrappers exist but are deprecated.

License in practice

MIT license permits commercial and private use with minimal restrictions; suitable for most projects.

Quickstart

pip install pyhanko-certvalidator

from pyhanko_certvalidator import CertificateValidator
validator = CertificateValidator()
# Use validator.validate_usage() or async equivalents for certificate validation

Verify before relying

  • Whether the synchronous API wrappers are stable enough for production use despite deprecation status
  • Performance comparison between requests-based (default) and aiohttp-based OCSP/CRL clients
  • Completeness of documentation for migration from synchronous to async patterns

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
asn1cryptooscryptocryptographyuritoolsrequests
MaintenanceActively maintained 20 days since the last release
Last repo commit
First released
Downloads6,294,287 / month, #1,937 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security :: Cryptography

Evidence: pyhanko_certvalidator-0.31.4-py3-none-any.whl

Tags

Capabilities
x.509 certificate validationcertificate path validationcrl ocsp revocation checkspki certificate validatorx509 path building
Topics
pkix509revocation-checking
PyPI keywords
cryptopkix509certificatecrlocsp

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “certificate path validation”

  • pyhanko-certvalidatorValidates X.509 certificate paths with support for revocation checks…
  • certvalidatorValidates X.509 certificates and certificate chains, supporting path…
  • certifiCertifi provides Mozilla's curated collection of root SSL…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also certvalidator · ocspbuilder · ocspresponder · aia · openssl-ocsp-responder · wincertstore · truststore · pyHanko · service-identity · asn1crypto